Skip to main content
Home > Solutions > Solutions by Use Case > MyID CMS, Entra ID + YubiKey

MyID + Entra ID + YubiKey

Issue, manage and revoke FIDO passkeys on YubiKeys through Microsoft Entra ID and MyID CMS. MyID CMS plugs into Entra ID's FIDO2 provisioning APIs to deliver full passkey lifecycle management and phishing-resistant, passwordless sign-in to Entra ID-protected apps, across cloud and hybrid environments. The same console also manages digital certificates, covering every credential on the key.

The solution

Enterprise FIDO passkey management with Entra ID

Intercede, Microsoft and Yubico have brought their platforms together so enterprises can issue and manage FIDO passkeys at scale. MyID CMS integrates with Microsoft Entra ID's FIDO2 provisioning APIs to register and lifecycle-manage passkeys on the YubiKey family for phishing-resistant sign-in to Entra ID-protected resources.

Passkeys, centrally issued

MyID CMS controls who is issued a passkey, on which YubiKey and under which policy. Each user enrols with their own physical key, while bulk tasks such as revocation run centrally, with every action authorised and recorded.

Phishing-resistant Entra sign-in

Passkeys authenticate users to Microsoft Entra ID-protected resources, delivering phishing-resistant, passwordless access.

Full passkey lifecycle

Every stage of the passkey's life, from issuance through expiry to revocation, managed centrally in MyID CMS with a full audit trail.

How it works

From issuance to sign-in

MyID CMS issues and manages the passkey; Microsoft Entra ID handles authentication.

1

Issue the passkey

MyID CMS registers a FIDO passkey on the user's YubiKey through Microsoft Entra ID's FIDO2 provisioning APIs.

2

Sign in, phishing-resistant

The user signs in to Entra ID-protected resources with the passkey for passwordless and phishing-resistant, in cloud or hybrid Entra ID.

3

Manage the lifecycle

Apply expiry policy and revoke passkeys centrally, including automatic revocation for leavers and fixed-term staff.

Benefits

Why manage passkeys with MyID

Simplified issuance & lifecycle

Simplified passkey issuance and lifecycle management, self-service or operator-led on a user's behalf, from the same MyID CMS console that manages your digital certificates.

Expiry and automatic revocation

Issue long-lived and short-lived passkeys side by side, with expiry dates and automatic revocation. Ideal for fixed-term contractors and temporary devices.

One CMS, every Entra ID tenant

Works with cloud and hybrid Microsoft Entra ID deployments, with consistent registration, reporting and lifecycle processes across multiple connected tenants.

NIST SP 800-63B aligned

Issue and manage passkeys in line with the NIST SP 800-63B digital identity guidelines.

Passkey as a derived credential

Supports using a passkey as a derived credential, compliant with NIST SP 800-157.

Trusted YubiKey hardware

Manage passkeys on the YubiKey family of hardware security keys, backed by the Intercede, Microsoft and Yubico collaboration.

Operator-led issuance

Prepare devices ready for new starters, or let line managers and security teams issue temporary devices on a user's behalf. Strict policy controls and a full audit trail cover every action.

One passkey per person

Stop passkeys multiplying across your organisation. MyID CMS can limit each person to a single active passkey, so you always know exactly what every user holds.

Reuse YubiKeys, improve ROI

When a device is handed back, MyID CMS erases it and returns it to the pool ready to reissue. Your hardware investment keeps working.

See passkey management with Entra ID and MyID

Book a walkthrough and we'll show FIDO passkeys issued and managed on YubiKeys with Microsoft Entra ID and MyID CMS.